Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY13 SECURITY RECORDS

glenwpcoder

Drag and Drop Multiple File Upload for Contact Form 7

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-8991 6 Jun 2026 ≤ 1.3.9.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-5718 17 Apr 2026 ≤ 1.3.9.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-5710 17 Apr 2026 ≤ 1.3.9.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-3459 5 Mar 2026 ≤ 1.3.9.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-14457 15 Jan 2026 ≤ 1.3.9.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-14842 7 Jan 2026 Drag and Drop Multiple File Upload for Contact Form 7: ≤ 1.3.9.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-8464 16 Aug 2025 ≤ 1.3.9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-3515 17 Jun 2025 ≤ 1.3.8.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-2485 28 Mar 2025 ≤ 1.3.8.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-2328 28 Mar 2025 ≤ 1.3.8.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-12267 31 Jan 2025 ≤ 1.3.8.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-3717 2 May 2024 ≤ 1.3.7.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-5822 22 Nov 2023 ≤ 1.3.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.